/srv/irclogs.ubuntu.com/2014/03/14/#ubuntu-motu.txt

=== emma_ is now known as emma
=== stgraber_ is now known as stgraber
=== kitterma is now known as ScottK
dholbachgood morning07:44
dkesselguten morgen dholbach07:53
dholbachhi dkessel07:53
j_f-fmoin08:06
ESphynxhey guys are you going to upgrde freetype for the LTS because there's a nasty double free in the current Trusty version17:07
rbasakESphynx: can you be more specific, please? Is there a bug for this? Which LTS, which version, what patch or upstream commit, etc.17:09
ESphynxrbasak : talking about Trusty, if there's not there should be :)17:20
ESphynxand latest upstream freetype fixes the problem17:20
ESphynx2.5.3 vs 2.5.2 which is currently in Trusty17:20
rbasakESphynx: looks like 2.5.3 isn't in Debian either. It can be picked up at this stage, but that's up to an Ubuntu developer familiar with the package. Looks like slangasek might be your man as he's a DM for the package as well.17:22
rbasakESphynx: but if you want it fixed, then you should file a bug to track that if there isn't one already.17:23
slangasekugh freetype17:26
ESphynxwhat should the bug be filed again?17:26
ESphynxagainst*17:26
ESphynxslangasek: yeah 2.5.2 is quite horrible17:26
ESphynxvery nasty double free.17:27
ESphynxon deleting a face17:27
slangasekthe security bugs are an issue, yes; but security bugs are fixed by backporting patches, not by taking new upstream versions (*especially* not new upstream versions of freetype, which are a grab bag of regressions and bugfixes)17:27
slangasekESphynx: is this the same as the security bug that has a CVE open for it (Debian bug #741299)?17:28
ubottuDebian bug 741299 in src:freetype "freetype: CVE-2014-2240, CVE-2014-2241: stack OOB read/write, DoS" [Grave,Open] http://bugs.debian.org/74129917:28
ESphynxno I dont think so17:28
ESphynxslangasek: http://savannah.nongnu.org/bugs/?40997  -- this is the one I was referring to18:22
ESphynxhmm sorry, this makes it look like it's not a free type bug :P18:23
ESphynxunrelated disregard :(18:23
ESphynxwhat I know is that 2.5.2 was crashing consistently and Valgrind complaining and after an update to 2.5.3 the problem was gone, but look through the commits diffs still have me puzzled as to why. I'll look into it a bit later today :)18:24
slangasekESphynx: it's reported to be fixed in freetype, and from the description I'd say it is a freetype bug18:47
ESphynxslangasek: Yeah my problem had to do with stream, but I got it on Linux not Windows...19:13
jtaylorgr missed the uds again oO21:26
=== e11bits_ is now known as e11bits
=== yofel_ is now known as yofel
=== Daviey_ is now known as Daviey

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!